summaryrefslogtreecommitdiff
path: root/scripts/Makefile.thinlto
diff options
context:
space:
mode:
authorTaimuraz Kaitmazov <taimuraz@kaitmazov.com>2026-08-18 03:00:19 +0300
committerLizhi Hou <lizhi.hou@amd.com>2026-08-24 09:29:47 -0700
commitef6d27af71e1dc43181ec797a6aaa77c27c36786 (patch)
treeb3b88c08fcc7f75569e594b85769d0e52baeca3e /scripts/Makefile.thinlto
parentb3709d354545e70388177500761f92d906c4dfd6 (diff)
accel/amdxdna: reject a command chain that carries no commands
A chain whose command_count is zero passes the payload length check, because struct_size(payload, data, 0) is just the header. The fill loop then does not run, so offset stays zero and the request is submitted with a zero-length buffer. On firmware without AIE2_NPU_COMMAND that ends at the opcode check, since op is still ERT_INVALID_CMD and aie2_get_chain_msg_op() answers MSG_OP_MAX_OPCODE. aie2_get_npu_chain_msg_op() answers MSG_OP_CHAIN_EXEC_NPU whatever it is given, so there the submission continues to drm_clflush_virt_range(cmd_buf, 0), which reads the byte before the buffer and faults on the vmap guard page. EXEC_CMD is reachable by any process that can open the render node. Reject the request instead. Fixes: 8ed8b0239617 ("accel/amdxdna: Add debug prints for command submission") Signed-off-by: Taimuraz Kaitmazov <taimuraz@kaitmazov.com> Reviewed-by: Lizhi Hou <lizhi.hou@amd.com> Signed-off-by: Lizhi Hou <lizhi.hou@amd.com> Link: https://patch.msgid.link/20260818000019.369366-1-taimuraz@kaitmazov.com
Diffstat (limited to 'scripts/Makefile.thinlto')
0 files changed, 0 insertions, 0 deletions